8.8

CVE-2022-42861

This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 15.7.2
Apple ≫ iPadOS Version >= 16.0 < 16.2
Apple ≫ iPhone OS Version < 15.7.2
Apple ≫ iPhone OS Version >= 16.0 < 16.2
Apple ≫ macOS Version < 12.6.2
Apple ≫ macOS Version 13.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA-ADP 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://seclists.org/fulldisclosure/2022/Dec/23
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/21
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/24
Third Party Advisory
Mailing List
https://support.apple.com/en-us/HT213532
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213533
Vendor Advisory
Release Notes
http://seclists.org/fulldisclosure/2022/Dec/20
Third Party Advisory
Mailing List
https://support.apple.com/en-us/HT213530
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213531
Vendor Advisory
Release Notes